Unrated severityNVD Advisory· Published Feb 22, 2024· Updated Sep 19, 2024
B&R products use insufficient communication encryption
CVE-2024-0220
Description
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Affected products
2- Range: 4.0
- B&R Industrial Automation/Technology Guardingv5Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.